notbugAs an Amazon Associate I earn from qualifying purchases.
Want a good read? Try FreeBSD Mastery: Jails (IT Mastery Book 15)
Want a good monitor light? See my photosAll times are UTC
Ukraine

Newsfeed changes

The news feed page[s] were not laid out well. Two pages, disjointed information, hard to figure out how to use the optional parameters...

Thankfully, someone told me.

The new page is ready for your review. Please compare these two:

You may also be interested in the Github issue.
non port: security/vuxml/vuln.xml

Number of commits found: 6273 (showing only 100 on this page)

[First Page]  «  8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18  »  [Last Page]

Wednesday, 28 Feb 2018
07:35 delphij search for other commits by this committer
Document multiple NTP vulnerabilities.
Original commitRevision:463184 
Tuesday, 27 Feb 2018
20:22 riggs search for other commits by this committer
Document CVE-2018-6056 in chromium 64.0.3282.167

Reported by:	Tommi Pernila <tommi.pernila@iki.fi> (via e-mail)
Original commitRevision:463160 
20:15 riggs search for other commits by this committer
Document multiple vulnerabilities in chromium 64.0.3282.119

Reported by:	Tommi Pernila <tommi.pernila@iki.fi> (via e-mail)
Original commitRevision:463159 
20:03 riggs search for other commits by this committer
Document CVE-2018-1304 and CVE-2018-1305 in Apache Tomcat

Submitted by:	Roger Marquis <marquis@roble.com> via e-mail
Original commitRevision:463158 
15:22 girgen search for other commits by this committer
Document security problems with shibboleth-sp

Security:	CVE-2018-0489
Original commitRevision:463145 
Sunday, 25 Feb 2018
19:39 joneum search for other commits by this committer
Document multiple vulnerabilities in www/drupal7 and www/drupal8

Security:	CVE-2017-6927
Security:	CVE-2017-6928
Security:	CVE-2017-6929
Security:	CVE-2017-6930
Security:	CVE-2017-6931
Security:	CVE-2017-6932
Original commitRevision:462974 
10:44 tota search for other commits by this committer
- Fix range for ja-mailman in CVE-2018-5950
Original commitRevision:462946 
Saturday, 24 Feb 2018
09:14 riggs search for other commits by this committer
Document ssh injection vulnerability in devel/cvs

PR:		226088
Reported by:	fk@fabiankeil.de
Security:	CVE-2017-12836
Original commitRevision:462782 
Friday, 23 Feb 2018
22:00 dbaio search for other commits by this committer
security/vuxml: Document vulnerability in editors/libreoffice

Security:	CVE-2018-6871

PR:		225797
Submitted by:	Vladimir Krstulja <vlad-fbsd@acheronmedia.com>
Original commitRevision:462748 
13:25 dbaio search for other commits by this committer
security/vuxml: Document vulnerabilities in www/squid

Security:	CVE-2018-1000024
Security:	CVE-2018-1000027

PR:		226138
Submitted by:	Yasuhiro KIMURA <yasu@utahime.org>
Original commitRevision:462696 
Thursday, 22 Feb 2018
19:42 dbaio search for other commits by this committer
security/vuxml: Fix freebsdpr entry (r462310)
Original commitRevision:462621 
10:16 madpilot search for other commits by this committer
Document new asterisk and pjsip vulnerabilities.
Original commitRevision:462579 
07:15 matthew search for other commits by this committer
Document the latest phpMyAdmin security advisory PMASA-2018-1
Original commitRevision:462564 
Wednesday, 21 Feb 2018
09:12 tz search for other commits by this committer
Document GitLab Vulnerability

Security:
https://vuxml.FreeBSD.org/freebsd/86291013-16e6-11e8-ae9f-d43d7e971a1b.html
Original commitRevision:462481 
Monday, 19 Feb 2018
12:24 dbaio search for other commits by this committer
security/vuxml: Document multiple vulnerabilities in irc/irssi

Security:	CVE-2018-7054
Security:	CVE-2018-7053
Security:	CVE-2018-7052
Security:	CVE-2018-7051
Security:	CVE-2018-7050

PR:		226001
Reported by:	tj@mrsk.me (email)
Reported by:	David O'Rourke <dor.bsd@xm0.uk>
Original commitRevision:462310 
Saturday, 17 Feb 2018
19:09 adamw search for other commits by this committer
Add Mojolicious vulnerability, for which there is very little
information about the actual issue.
Original commitRevision:462187 
09:42 ohauer search for other commits by this committer
- document bugzilla44 and bugzilla50 CVE issue
Original commitRevision:462088 
Friday, 16 Feb 2018
16:56 leres search for other commits by this committer
Mark bro < 2.5.3 as vulnerable as per:

    http://blog.bro.org/2018/02/bro-253-released-security-update.html

Reviewed by:	matthew (mentor)
Approved by:	matthew (mentor)
Differential Revision:	https://reviews.freebsd.org/D14395
Original commitRevision:462045 
15:43 sunpoet search for other commits by this committer
Fix typo
Original commitRevision:462043 
03:38 swills search for other commits by this committer
Document consul issue
Original commitRevision:461972 
01:02 leres search for other commits by this committer
Mark bro < 2.5.2 as vulnerable as per:

    http://blog.bro.org/2017/10/bro-252-242-release-security-update.html

Reviewed by:	ler (mentor)
Approved by:	ler (mentor)
Security:	CVE-2017-1000458
Differential Revision:	https://reviews.freebsd.org/D14394
Original commitRevision:461961 
Thursday, 15 Feb 2018
22:20 pi search for other commits by this committer
security/vuxml: 4 CVEs for net/quagga
Original commitRevision:461954 
17:42 jhale search for other commits by this committer
Document vulnerabilities in graphics/libraw
Original commitRevision:461939 
Wednesday, 14 Feb 2018
21:02 yuri search for other commits by this committer
VulnXML: Bitmessage vulnerability

No CVE is available. CVE is requested.
The bitmessage port will be updated shortly.

Approved by:	tcberner
Original commitRevision:461837 
17:42 swills search for other commits by this committer
Document Jenkins vulnerability
Original commitRevision:461823 
Tuesday, 13 Feb 2018
23:40 yuri search for other commits by this committer
VulnXML records for vulnerabilities of sysutils/bchunk fixed in the upcoming
update to 1.2.2 (bug#225772)

Approved by:	tcberner (mentor, implicit)
Original commitRevision:461758 
09:23 vsevolod search for other commits by this committer
- Document www/uwsgi vulnerability
Original commitRevision:461689 
09:16 vsevolod search for other commits by this committer
- Fix URL in blockquote

Reported by:	remko via private email
Original commitRevision:461688 
Sunday, 11 Feb 2018
22:03 cpm search for other commits by this committer
Correct affected version of Mpv
Original commitRevision:461532 
16:52 sunpoet search for other commits by this committer
Document python vulnerability
Original commitRevision:461511 
11:00 ehaupt search for other commits by this committer
Document vulnerability in finance/electrum and finance/electrum2.

PR:		225056
Submitted by:	pete@nomadlogic.org, vermaden@interia.pl (via mail)
Security:	CVE-2018-6353
Original commitRevision:461487 
Saturday, 10 Feb 2018
21:45 dbaio search for other commits by this committer
security/vuxml: Document vulnerability in net-p2p/libtorrent

PR:		224664
Reported by:	Henry David Bartholomew <PopularMoment@protonmail.com>
Original commitRevision:461436 
19:29 vsevolod search for other commits by this committer
- Document CVE-2018-6789 in mail/exim

Security:	316b3c3e-0e98-11e8-8d41-97657151f8c2
Original commitRevision:461413 
10:57 rakuco search for other commits by this committer
Add entries for CVE-2017-17969 and CVE-2018-5996 in p7zip

Security:	CVE-2017-17969
Security:	CVE-2018-5996
Original commitRevision:461378 
Friday, 9 Feb 2018
20:03 cpm search for other commits by this committer
Document vulnerability in Mpv

PR:		225783
Submitted by:	Vladimir Krstulja <vlad-fbsd@acheronmedia.com>
Obtained from:	https://nvd.nist.gov/vuln/detail/CVE-2018-6360
Security:	CVE-2018-6360
Original commitRevision:461331 
Thursday, 8 Feb 2018
22:38 mandree search for other commits by this committer
Extend mailman CVE-2018-5950 vuln entry to mailman-with-htdig

Security:	3d0eeef8-0cf9-11e8-99b0-d017c2987f9a
Security:	CVE-2018-5950
Original commitRevision:461278 
22:23 mandree search for other commits by this committer
Document Mailman vulnerability

PR:		225767
Submitted by:	Vladimir Krstulja
Reviewed by:	Matthias Andree
Security:	CVE-2018-5950
Security:	3d0eeef8-0cf9-11e8-99b0-d017c2987f9a
Original commitRevision:461276 
17:32 girgen search for other commits by this committer
Add security notice for PostgreSQL

Security:	CVE-2018-1052
Security:	CVE-2018-1053
Original commitRevision:461250 
17:02 pi search for other commits by this committer
security/vuxml: Document recent tiff CVEs

PR:		225545
Submitted by:	Yasuhiro KIMURA <yasu@utahime.org>
Original commitRevision:461249 
Tuesday, 6 Feb 2018
21:39 jkim search for other commits by this committer
Document the latest Flash Player vulnerability.

https://helpx.adobe.com/security/products/flash-player/apsb18-03.html
Original commitRevision:461112 
01:38 leres search for other commits by this committer
Mark mini_httpd < 1.28 and thttpd < 2.28 as vulnerable as per:

    http://acme.com/updates/archive/199.html

While we're here, fix whitespace in vuln.xml that "make validate"
flagged.

Reviewed by:	ler (mentor)
Approved by:	ler (mentor)
Security:	CVE-2017-17663
Differential Revision:	D14217
Original commitRevision:461033 
Monday, 5 Feb 2018
05:07 yuri search for other commits by this committer
Adding VuXML record for vulnerability CVE-2017-15924 in net/shadowsocks-libev.

D14200 (part I).

The next commit will update net/shadowsocks-libev and fix this
vulnerability.

PR:		225442
Submitted by:	myself
Approved by:	adamw (mentor)
Differential Revision:	https://reviews.freebsd.org/D14200
Original commitRevision:460961 
Saturday, 3 Feb 2018
18:10 nobutaka search for other commits by this committer
Add modification date for the entry of w3m vulnerabilities.

Spotted by:	 dbaio
Original commitRevision:460830 
13:35 nobutaka search for other commits by this committer
Update entry of w3m vulnerabilities.

PR:		225611
Submitted by:	D. Ebdrup <debdrup@gmail.com>
Original commitRevision:460811 
10:27 tobik search for other commits by this committer
Document www/palemoon vulnerabilities

PR:		225644
Security:	CVE-2018-5102
Security:	CVE-2018-5122
Original commitRevision:460802 
Friday, 2 Feb 2018
19:55 sunpoet search for other commits by this committer
Document django vulnerability
Original commitRevision:460749 
18:20 brd search for other commits by this committer
Document vulns in www/w3m.

PR:		225611
Submitted by:	D. Ebdrup <debdrup@gmail.com>
Original commitRevision:460722 
Thursday, 1 Feb 2018
13:26 zeising search for other commits by this committer
Update range for dovecot vulnerability.
Original commitRevision:460595 
Wednesday, 31 Jan 2018
21:38 jbeich search for other commits by this committer
security/vuxml: mark waterfox < 56.0.3.65 as vulnerable
Original commitRevision:460540 
Tuesday, 30 Jan 2018
17:20 zeising search for other commits by this committer
Add modified date, forgotten in r460325
Original commitRevision:460416 
00:53 jbeich search for other commits by this committer
security/vuxml: mark firefox < 58.0.1 as vulnerable
Original commitRevision:460356 
00:53 jbeich search for other commits by this committer
security/vuxml: bump min waterfox version with FF58 fixes
Original commitRevision:460355 
Monday, 29 Jan 2018
21:17 tijl search for other commits by this committer
Update range for linux-*-nss.

PR:		225541
Submitted by:	dbn
Security:	https://access.redhat.com/errata/RHSA-2017:2832
Original commitRevision:460338 
19:17 zeising search for other commits by this committer
FIx range for dovecot

2.2.33.2_2 is vulnerable.
Original commitRevision:460325 
Saturday, 27 Jan 2018
09:10 kwm search for other commits by this committer
Document gcab stack overflow.

Security:	CVE-2018-5345
Original commitRevision:460077 
Friday, 26 Jan 2018
14:37 swills search for other commits by this committer
Document dovecot issue

Submitted by:	Roger Marquis <marquis@roble.com>
Original commitRevision:459994 
14:28 swills search for other commits by this committer
Document curl issue

Submitted by:	Roger Marquis <marquis@roble.com>
Original commitRevision:459993 
13:23 cmt search for other commits by this committer
document recent clamav vulnerabilities

See: http://blog.clamav.net/2018/01/clamav-0993-has-been-released.html
Original commitRevision:459991 
09:00 amdmi3 search for other commits by this committer
Fix wordpress entries in vuxml

- Fix incorrect package names
- Fix epoch in older entry which makes it incorrectly report fresh ports as
vulnerable

With hat:	ports-secteam
Original commitRevision:459977 
Tuesday, 23 Jan 2018
23:07 jbeich search for other commits by this committer
security/vuxml: seamonkey 2.49.2 will use firefox-esr 52.6 engine
Original commitRevision:459805 
18:43 jbeich search for other commits by this committer
security/vuxml: mark firefox < 58 as vulnerable
Original commitRevision:459791 
11:33 krion search for other commits by this committer
Fix typo.
Original commitRevision:459745 
11:23 krion search for other commits by this committer
Document new vulnerability in dns/powerdns-recursor < 4.1.1

Obtained
from:	https://doc.powerdns.com/recursor/security-advisories/powerdns-advisory-2018-01.html
Security:	CVE-2018-1000003
Original commitRevision:459743 
02:05 cpm search for other commits by this committer
Document new vulnerabilities in www/chromium < 63.0.3239.108

Obtained
from:	https://chromereleases.googleblog.com/2017/12/stable-channel-update-for-desktop_14.html
Security:	CVE-2017-15429
Original commitRevision:459722 
01:53 cpm search for other commits by this committer
Document new vulnerabilities in www/chromium < 63.0.3239.84

Obtained
from:	https://chromereleases.googleblog.com/2017/12/stable-channel-update-for-desktop.html
Original commitRevision:459721 
00:39 cpm search for other commits by this committer
Document new vulnerability in www/chromium < 62.0.3202.94

Obtained
from:	https://chromereleases.googleblog.com/2017/11/stable-channel-update-for-desktop_13.html
Security:	CVE-2017-15428
Original commitRevision:459716 
Monday, 22 Jan 2018
23:47 cpm search for other commits by this committer
Add missing entry for www/chromium

Security:	CVE-2017-15406
Original commitRevision:459709 
Friday, 19 Jan 2018
16:43 girgen search for other commits by this committer
Add more information about the recents security notice for shibboleth2-sp
Original commitRevision:459437 
15:12 dbaio search for other commits by this committer
security/vuxml: Document vulnerability in dns/unbound

Security:	CVE-2017-15105

PR:		225313
Reported by:	jaap@NLnetLabs.nl
Original commitRevision:459430 
13:01 joneum search for other commits by this committer
Document phpbb3 issues

Approved by:	tz (mentor)
Differential Revision:	https://reviews.freebsd.org/D13983
Original commitRevision:459412 
12:45 brnrd search for other commits by this committer
security/vuxml: Fix tabs and spaces settings
Original commitRevision:459409 
12:44 brnrd search for other commits by this committer
security/vuxml: Document 2018Q1 Oracle MySQL vulns
Original commitRevision:459408 
06:15 joneum search for other commits by this committer
Document wordpress issues

Approved by:	tcberner (mentor)
Differential Revision:	https://reviews.freebsd.org/D13954
Original commitRevision:459397 
Wednesday, 17 Jan 2018
20:50 swills search for other commits by this committer
Document GitLab issue
Original commitRevision:459287 
Sunday, 14 Jan 2018
02:19 woodsb02 search for other commits by this committer
Document DNS rebinding vulnerabilities in net-p2p/transmission-daemon

PR:		225150
Security:	https://www.vuxml.org/freebsd/3e5b8bd3-0c32-452f-a60e-beab7b762351.html
Original commitRevision:458952 
Friday, 12 Jan 2018
17:23 girgen search for other commits by this committer
Document vulnerability of devel/xmltooling

security/shibboleth2-sp depends on the xmltooling port

Security:	CVE-2018-0486
Original commitRevision:458859 
Thursday, 11 Jan 2018
21:18 adamw search for other commits by this committer
Add vim-console instead of replacing vim-list.

Reported by:	ohauer
Original commitRevision:458796 
20:36 adamw search for other commits by this committer
Chase the vim-lite -> vim-console rename
Original commitRevision:458789 
Tuesday, 9 Jan 2018
21:25 jkim search for other commits by this committer
Document the latest Flash Player vulnerability.

https://helpx.adobe.com/security/products/flash-player/apsb18-01.html
Original commitRevision:458576 
Monday, 8 Jan 2018
23:03 dbaio search for other commits by this committer
security/vuxml: Document vulnerability in www/awstats

Security:	CVE-2017-1000501

PR:		225007
Reported by:	Vidar Karlsen <vidar@karlsen.tech>
Original commitRevision:458494 
Saturday, 6 Jan 2018
20:43 dbaio search for other commits by this committer
security/vuxml: Document multiple vulnerabilities in irc/irssi

Security:	CVE-2018-5205
Security:	CVE-2018-5206
Security:	CVE-2018-5207
Security:	CVE-2018-5208

PR:		224954
Reported by:	tj@mrsk.me (email)
Reported by:	David O'Rourke <dor.bsd@xm0.uk>
Original commitRevision:458288 
Friday, 5 Jan 2018
17:17 jbeich search for other commits by this committer
security/vuxml: mark firefox < 57.0.4 as vulnerable
Original commitRevision:458155 
00:40 ultima search for other commits by this committer
* Add modified date to for libevhtp vulnerable
Thank you dbaio for catching this.
Original commitRevision:458095 
Thursday, 4 Jan 2018
19:08 ultima search for other commits by this committer
* Add libevhtp to list of vulnerable ports.

Libevhtp prior to 1.2.14 uses oniguruma 5.9.2 and is
vulnerable if using the REGEX option, which is the
default.
Original commitRevision:458042 
Sunday, 31 Dec 2017
14:48 dbaio search for other commits by this committer
security/vuxml: Fix FreeBSD PR bugs references
Original commitRevision:457696 
Saturday, 30 Dec 2017
16:41 dbaio search for other commits by this committer
security/vuxml: Document vulnerabilities in www/otrs

Security:	CVE-2017-16664
Security:	CVE-2017-16854
Security:	CVE-2017-16921

PR:		224729
Reported by:	Vidar Karlsen <vidar@karlsen.tech>
Original commitRevision:457604 
Friday, 29 Dec 2017
09:28 eugen search for other commits by this committer
Fix cut-n-paste error in the previous addition for bouncycastle15
(6a131fbf-ec76-11e7-aa65-001b216d295b).
Original commitRevision:457503 
09:23 eugen search for other commits by this committer
Document security defect in the Bouncy Castle Crypto APIs: CVE-2017-13098
("ROBOT")

Obtained from:  https://www.bouncycastle.org/releasenotes.html
Security:      
https://vuxml.FreeBSD.org/freebsd/6a131fbf-ec76-11e7-aa65-001b216d295b
Original commitRevision:457501 
Monday, 25 Dec 2017
11:31 jbeich search for other commits by this committer
security/vuxml: mark thunderbird < 52.5.2 as vulnerable
Original commitRevision:457217 
Saturday, 23 Dec 2017
17:03 matthew search for other commits by this committer
Document phpMyAdmin PMSA-2017-9: Critical XSRF/CSRF vulnerability.
Original commitRevision:457086 
10:24 brnrd search for other commits by this committer
security/vuxml: Fix typo in CVE number of latest Oracle CPU entry
Original commitRevision:457039 
09:55 madpilot search for other commits by this committer
Document new asterisk vulnerability.
Original commitRevision:457035 
09:16 brnrd search for other commits by this committer
security/vuxml: Document new MariaDB vuln

 - This is likely to also affect MySQL and other versions
   see https://security-tracker.debian.org/tracker/CVE-2017-15365
Original commitRevision:457029 
Wednesday, 20 Dec 2017
14:10 ehaupt search for other commits by this committer
Document multiple vulnerabilities in rsync.

PR:		224478
Submitted by:	yasu@utahime.org
Original commitRevision:456796 
Tuesday, 19 Dec 2017
02:15 swills search for other commits by this committer
Document ruby issue
Original commitRevision:456699 
Monday, 18 Dec 2017
21:48 asomers search for other commits by this committer
Add vuxml entry for CVE-2017-16355 to rubygem-passenger

The vulnerable version was already replaced by r452356

Reviewed by:	brd
Approved by:	brd (ports)
Sponsored by:	Spectra Logic Corp
Differential Revision:	https://reviews.freebsd.org/D13482
Original commitRevision:456676 
Sunday, 17 Dec 2017
18:50 zeising search for other commits by this committer
Document multiple vulnerabilities in libXfont and libXfont2.

The first two vulnerabilities are memory leaks when reading past valid
memory.

The last vulnerability is the possibility for an unprivileged X client to
read privileged files through symlinks

CVE-2017-13720
CVE-2017-13722
CVE-2017-16611
Original commitRevision:456560 
15:27 zeising search for other commits by this committer
Add CVE to references.
Original commitRevision:456539 
15:23 zeising search for other commits by this committer
Document x11/libXcursor -- integer overflow that can lead to heap buffer
overflow.

CVE-2017-16612
Original commitRevision:456537 
Saturday, 16 Dec 2017
20:54 sunpoet search for other commits by this committer
Document global vulnerability
Original commitRevision:456488 

Number of commits found: 6273 (showing only 100 on this page)

[First Page]  «  8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18  »  [Last Page]